Indexed by:
Abstract:
Internet purification is a necessary technique to defend against Distributed Denial-of-Service (DDoS) attack. It can help Internet Service Provider (ISP) to completely and precisely scrub attack traffic through establishing the sender-receiver pair based filtering rules in networks. However, when faced with the Link Flooding Attacks (LFA), a new kind of DDoS, existing relevant schemes suffer the drawbacks, including the weak willingness of defense cooperation between Autonomous Systems (ASes), lower filtering efficiency and poor robustness. For this, we propose STOP, a service-oriented Internet purification technique designed to defend against LFA. In STOP, malicious traffic filtering is viewed as a value-added service and each filter contributor (i.e., AS) can get some benefit from it. This helps ASes to strengthen the willing of defense cooperation. Moreover, we devise a filter recommendation algorithm to maximize the filtering efficiency, with minimum service cost and bandwidth damages. Furthermore, in the face of the strategic threats that aim to paralyze or bypass STOP, we devise relevant defense techniques to make it more robust. Through rigorous mathematical analysis and extensive experiments based on real-world topology, we demonstrate that compared with prior work, STOP increases the filtering efficiency by 12%.
Keyword:
Reprint 's Address:
Email:
Version:
Source :
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY
ISSN: 1556-6013
Year: 2022
Volume: 17
Page: 938-953
6 . 8
JCR@2022
6 . 3 0 0
JCR@2023
ESI Discipline: COMPUTER SCIENCE;
ESI HC Threshold:61
JCR Journal Grade:1
CAS Journal Grade:1
Cited Count:
SCOPUS Cited Count: 3
ESI Highly Cited Papers on the List: 0 Unfold All
WanFang Cited Count:
Chinese Cited Count:
30 Days PV: 2
Affiliated Colleges: